First published: Thu Aug 31 2023(Updated: )
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote attackers to read specific files via unspecified vectors.
Credit: security@synology.com security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Router Manager | <1.3.1-9346-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41740 is an improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in the cgi component in Synology Router Manager (SRM) before version 1.3.1-9346-6.
CVE-2023-41740 allows remote attackers to read specific files in Synology Router Manager (SRM) through unspecified vectors.
CVE-2023-41740 has a severity rating of 5.3, which is classified as medium.
The CWE ID for CVE-2023-41740 is CWE-22.
To fix CVE-2023-41740, update Synology Router Manager (SRM) to version 1.3.1-9346-6 or later. Refer to the Synology Security Advisory Synology_SA_23_10 for more information.